Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Malwarebytes’ March 2025 survey found that 44% of respondents said they encounter a mobile scam every day, while 78% said they encounter one at least weekly. The findings point to frequent exposure, serious consequences, and low reporting—but they are self-reported results from a Malwarebytes-commissioned survey, not a population-wide count of confirmed crimes.
For smartphone users, the practical lesson is straightforward: treat unexpected delivery alerts, bank warnings, QR codes, login requests, familiar-looking calls, and urgent messages as potential social-engineering attempts. Pause, verify independently, and act quickly if you have already responded.
What Malwarebytes studied
The research, titled Tap, Swipe, Scam: How everyday mobile habits carry real risk, was conducted in March 2025. Malwarebytes says it surveyed 1,300 adults aged 18 and over in the United States, United Kingdom, Austria, Germany, and Switzerland.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The company says the sample had an equal gender split and was spread across ages, regions, and racial groups, with weighting intended to provide a balanced view. The research was distributed through Forsta with the involvement of an independent research consultant.
#1 Best Overall
Those details provide useful context, but the press materials do not establish a nationally representative probability sample, a margin of error, or an independently verified count of criminal incidents. The percentages below should therefore be read as reports from Malwarebytes’ survey respondents, not as a measurement of every mobile user.
Read Malwarebytes’ official announcement.
The survey’s key numbers
| Finding | Reported figure | How to interpret it |
|---|---|---|
| Encountered a mobile scam daily | 44% | Respondents reported seeing or receiving scam activity every day; this does not mean they lost money daily. |
| Encountered one at least weekly | 78% | Reported frequency of exposure, not independently measured message volume. |
| Encountered social engineering | 74% | Included examples such as phishing, fake delivery notices, and romance scams. |
| Fell victim to a mobile scam | 36% | A self-reported victimization measure; it should not automatically be treated as confirmed financial loss. |
| Found scams difficult to distinguish from legitimate messages | 66% | Shows how easily malicious communication can resemble ordinary business or personal outreach. |
| Strongly agreed they could recognize a scam | 15% | Reported confidence was low, despite frequent exposure. |
| Worried about mobile scams | 77% | Measures concern, not the number of people who experienced a particular attack. |
| Worried about AI making scams more realistic | 66% | Measures concern about future or evolving threats, not confirmed exposure to AI-generated scams. |
“Encountered” can mean receiving or seeing a suspicious interaction. It is not the same as clicking, paying, surrendering credentials, or suffering identity theft. Likewise, “victim” may cover different kinds of harm, so the denominators matter.
What mobile scams look like in practice
Mobile scams are not one technical category. They are often social-engineering attacks designed to create urgency, trust, fear, or curiosity.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems- Smishing and phishing: texts or emails that imitate a bank, retailer, employer, government agency, or delivery company.
- Fake delivery alerts: a message claims that a package needs a small fee, address confirmation, or login.
- Impersonation: a caller or message appears to come from a family member, bank, manager, official agency, or romantic partner.
- Malicious links and QR codes: the destination may be a fake login page, payment form, or malware download.
- Romance, job, and investment scams: the relationship or opportunity develops over time before the request for money or access.
- Extortion and sextortion: a criminal threatens to publish intimate images or private information.
- Virtual kidnapping and emergency scams: the criminal claims that a relative is in danger and demands immediate payment.
- Account-takeover attempts: the target is pushed to reveal a password, one-time code, recovery phrase, or approval notification.
- Fake security or technical-support alerts: a supposed infection or account problem is used to obtain payment or remote access.
A legitimate company may use a short link or QR code, and a real delivery may coincide with a fake delivery message. That is why appearance alone is unreliable. Do not use the phone number or link supplied by the suspicious message. Find the organization’s official website or use a known number instead.
Rank #2
The reported damage goes beyond lost money
Among respondents identified as scam victims, Malwarebytes reports that:
- 52% suffered financial loss or fraud. This wording is broader than “52% lost money.”
- 18% had to freeze their credit.
- 15% permanently lost money.
- 8% had accounts fraudulently opened in their name.
- 27% lost access to important digital assets, including accounts, devices, or irreplaceable files.
- 25% were harassed or blackmailed.
- 19% had private information exposed.
These outcomes are different. A temporary account restriction is not the same as permanent financial loss; fraudulent account creation is different from a stolen password; and exposure of private information can create long-term risk even when no payment was made.
Malwarebytes also says 75% of scam victims experienced serious emotional consequences, while 46% reported effects such as anxiety, depression, or loss of trust. These are self-reported survey responses, not clinical diagnoses. The figures nevertheless show why recovery cannot be reduced to deleting an app or changing one password.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Why many victims do not report scams
Only 17% of victims in the Malwarebytes survey said they reported scams to authorities. The figure fell to 14% among younger generations. “Reported to authorities” is narrower than telling a bank, carrier, platform, friend, or family member, and the survey cannot measure all incidents missing from official statistics.
Rank #3
People may stay silent because they feel ashamed, fear being judged, believe authorities cannot help, do not know where to report, or think the loss is too small to matter. Extortion victims may fear retaliation, while others may have deleted messages or worry that reporting will expose sensitive information.
The release also cites FBI Internet Crime Complaint Center data showing $16.6 billion in reported cybercrime losses in 2024, with cyber-enabled fraud accounting for almost 83% of reported losses. That is a broader FBI dataset—not a count of mobile-scam losses—and it should not be merged with the Malwarebytes survey figures.
Gen Z and extortion-related scams
Malwarebytes reports that 58% of Gen Z respondents encountered an extortion scam and 28% said they fell victim. Its comparison figures were 35% encountered and 15% victimized among Gen X, and 23% encountered and 7% victimized among boomers.
Free tools Windows power users keep installed
One-click scans. No signup required.
Gen Z reported the highest figures in these age-group comparisons, but the survey does not prove that age alone causes vulnerability. Different generations may use different platforms, encounter different kinds of contact, or classify an incident as extortion differently. No age group is immune to impersonation, coercion, or fraud.
What AI changes—and what this survey does not prove
Malwarebytes says AI tools can lower the barrier for criminals to create convincing messages, images, voices, and impersonations. Synthetic voice and video, polished phishing copy, personalized targeting, and faster campaign creation could make familiar warning signs less reliable.
However, the survey’s 66% figure measures concern about how realistic AI-enabled scams may become. It does not establish how many respondents were targeted with generative-AI text, deepfakes, or voice cloning. A realistic image or voice is still not proof of identity: verify through a separate channel, especially when money, access codes, or intimate material is involved.
What to do when a message looks suspicious
- Stop communicating. Do not argue with or reassure the sender.
- Do not click, scan, open, install, or pay. Avoid links, QR codes, attachments, apps, remote-access tools, gift cards, cryptocurrency transfers, and one-time-code requests.
- Verify independently. Type the organization’s known website into your browser or call a number from a statement, card, or official website—not from the message.
- Preserve evidence. Save screenshots, numbers, usernames, URLs, timestamps, payment records, and relevant account details before deleting anything.
- Secure compromised accounts. If you entered a password, change it from a clean device and enable multifactor authentication. Change it anywhere else it was reused.
- Contact the payment provider immediately. Call your bank, card issuer, payment service, or cryptocurrency exchange if money or financial details were involved. A security app cannot reverse a completed payment.
- Protect your identity. Freeze or monitor credit where appropriate after exposing identity information, and contact the mobile carrier if a SIM swap or account takeover is suspected.
- Report it. Use the relevant platform’s reporting tools and the appropriate government or law-enforcement channel in your country.
- Tell someone you trust. A second person can help verify messages and reduce pressure to act alone.
- Prioritize safety in threats or sextortion. Do not pay a blackmailer or send more material. Preserve evidence, seek law-enforcement or crisis-support help, and get immediate assistance if there is a risk of physical harm.
If you already clicked
Close the page and do not enter information. Update the device and run the security checks available on your platform. If you installed an app or remote-access tool, disconnect it, uninstall it if safe to do so, and seek trusted technical help.
If you entered a password or code
Use a clean device to change the password, revoke active sessions where the service permits it, enable multifactor authentication, and contact the service provider. Never share a new verification code with someone who calls claiming to help.
Best Value
Scam Guard: an optional analysis layer
Malwarebytes Scam Guard is an AI-powered feature integrated into Malwarebytes products. Malwarebytes says users can submit suspicious texts, emails, phone numbers, links, images, messages, or screenshots for an assessment and recommendations.
On iOS/iPadOS and Android, the documented workflow is:
- Open the Malwarebytes app.
- Under Security, tap AI Scam Guard.
- Choose a prompt or type a question.
- Tap the paperclip icon and attach a screenshot.
- Select the screenshot, tap Add, then tap the blue arrow to submit it.
- Review the response about whether the content appears suspicious or is a known threat.
Malwarebytes’ current help documentation lists Scam Guard as free, while the app itself is free to download and broader features vary by operating system and subscription. Check the current plan and storefront details before subscribing.
Recommended Free Tools
Scam Guard is advisory, not a guarantee. New scams may not yet be flagged, and a “not detected” result is not permission to click. It is also user-initiated analysis rather than automatic prevention of every scam. Redact passwords, one-time codes, full account numbers, recovery phrases, medical details, and intimate images before uploading screenshots. Malwarebytes says submitted queries are stored locally for 30 days for convenience and that reported scams may be added to its protection database; review the current documentation if that matters to your privacy decision.
Built-in messaging, browser, and call protections; carrier spam filters; password managers; multifactor authentication; bank alerts; and credit-freeze services can all provide useful layers. A VPN may protect some network traffic, but it does not identify a scammer or prevent social engineering. Caller-ID labels are helpful but fallible because numbers and accounts can be spoofed.
Quick Recap
What the research can—and cannot—tell us
- It indicates that Malwarebytes’ respondents reported frequent exposure to mobile scams.
- It documents self-reported victimization, financial and digital consequences, emotional effects, and reporting behavior.
- It does not measure every mobile user, establish a universal daily attack rate, or provide independently verified incident counts.
- It cannot prove that age causes vulnerability or that AI-generated content caused a particular incident.
- Its percentages use different denominators, including all respondents, reported victims, and age groups.
- Because Malwarebytes commissioned the research and sells the security products discussed, its findings and product claims deserve attribution rather than presentation as neutral, independent population research.
Before you tap: a five-second checklist
- Pause: urgency is a common manipulation tactic.
- Verify: use an independent website or known phone number.
- Protect codes: no legitimate helper needs your one-time login code.
- Secure accounts: use unique passwords and multifactor authentication.
- Act quickly after payment: call the bank or payment provider immediately.
- Preserve and report: save evidence and report without shame.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

